Is CrashPlan HIPAA compliant?
When evaluating software for HIPAA compliance you need to examine how the product handles security issues (passwords, transmission, encryption, etc.) In these areas, CrashPlan is HIPAA compliant and here’s why: Data is backed up symmetrically at the source. If you use the Private Password option, your files cannot be decrypted at the destination without your data password. With the Private Password enabled, only someone who can supply the correct private data password is allowed to restore your files. The private data password is never sent to CrashPlan, and therefore CrashPlan Support cannot retrieve or restore this password for you if you lose it. CrashPlan (the free version) uses 128-bit Blowfish to encrypt your files. CrashPlan+ uses 448-bit Blowfish encryption, which is much stronger than the 128-bit encryption that online banking and most businesses use. Put simply, if someone ever accessed your backup archive, both your password and encryption key are needed to decrypt your data